The number of seconds to be applied as back-off for all the times sent to Entrust Certificate Authority authorities when querying over a time range. While this increases the number of repeated records, it allows adjustments that ensure times are properly overlapping in their environment.

  • When the Entrust Certificate Authority authority is ahead of CA Gateway, there is an increase in the number of previously retrieved records in subsequent queries. This expected behavior is due to grey zone issues and causes no problem for the client. In this scenario, clock drift tolerance only increases the probability of more previously retrieved records being returned and does not generate an error.
  • Detecting when the Entrust Certificate Authority authority has fallen behind is more complicated as it only manifests when observed state changes are not in the query's result. In this case, clock drift tolerance allows evaluating how many seconds back-off the queries sent to Entrust Certificate Authority.

Time drift can continue over time, possibly resulting in the drift falling outside the configured value. Thus, constant monitoring of the times is needed, and periodic changes may become necessary.

Setting this parameter is an expert-level configuration.

Mandatory: No. This optional value defaults to 0.